Before you connect AI to your accounts, your data, or your customers' data — here's what you need to know.
For most of the last two years, AI was an assistant. It answered questions, drafted text, summarised documents. The risks were real, but they were contained.
That era is ending.
AI is now becoming the doer. Agents read your calendar, send your emails, push your code, update your customer records, post on your behalf, file your invoices, run your workflows — connected to your accounts, your data, and increasingly, the data of people who never agreed to it.
And the truth is: everyone's connecting things. Almost no one is understanding the risks.
This page is a quick orientation in what the agentic AI shift actually means, what risks it introduces, and the foundation you need before you start connecting AI to anything that matters.
What's actually different now
Each maps to one of the 8 pillars of the AI The Right Way® framework — the foundation we teach.
Agents now need OAuth tokens to your email, calendar, CRM, code repos and bank dashboards. Each one is a permanent open door. Are you tracking what has access to what, and revoking it when you stop using it?
Pillar: PrivacyWhen an agent reads your inbox, it reads the data of everyone who emailed you. When it updates customer records, it's handling third-party PII. Their consent didn't come with your subscription.
Pillar: EthicsAn AI that gives a bad answer is a problem. An AI that takes a bad action — sends the wrong email, deletes the wrong file, makes the wrong booking — is a different problem entirely. Errors now have consequences in the real world.
Pillar: Critical ThinkingMCPs, plug-ins, custom GPTs, marketplace agents. Most organisations have no inventory of what's connected, what permissions it has, or whether it's still being used. The shadow IT problem just gained agency.
Pillar: ToolingWhen an agent reads emails, web pages or documents and acts on them, attackers can hide instructions inside that content. Your "trusted" AI now follows a stranger's orders. This is not theoretical — it's happening.
Pillar: StrategyWhen an agent does something wrong, who's accountable? The user? The platform? The organisation? Without logging, transparency, and review processes, "the AI did it" becomes the new excuse — and nobody learns.
Pillar: CultureThe AI The Right Way® framework was built so people and organisations have a structured way to evaluate, govern and apply AI responsibly — across every role and every industry. The pillars don't change because AI got more capable. They become more important.